Doubts cast over efficacy of two-factor authentication
Doubts cast over efficacy of two-factor authentication

Hackers can beat security tokens

Two-factor authentication 'doesn't solve anything', claims security expert

Iain Thomson

IT security expert Bruce Schneier has warned that plans to move to two-factor authentication will not solve online fraud.

Schneier pointed out that the tokens will not stop the most common types of attacks. Tokens can work well in corporate environments but will be ineffective against much of today's crime since it relies on tricking users rather than beating passwords.

Advertisement

"Two-factor authentication doesn't solve anything. It won't work for remote authentication over the internet," he said.

"I predict that banks and other financial institutions will spend millions fitting their users with two-factor authentication tokens.

"Early adopters of this technology may very well experience a significant drop in fraud for a while as attackers move to easier targets, but in the end there will be a negligible drop in the amount of fraud and identity theft."

He lists two attacks, man-in-the-middle and Trojans, which would not be stopped by the use of tokens. In the first case a hacker sets up a fraudulent phishing website such as a bank log-in page where the victim inputs their log in details anyway, and with Trojans the hacker would log in with the user, token or no token.

Last year online fraudsters stole $1.2bn in the US and there are fears that fraud is harming confidence in e-commerce.

Representatives of the British banking industry, police and the security industry met in January to discuss ways of fighting online fraud, including the introduction of tokens. Last year AOL launched a premium service for customers using the devices.

Microsoft announced yesterday that it is dropping passwords in favour of two-factor authentication.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

InfoSecurity Europe 2005

Online crime spirals out of control

New threats demand new practices, warns security expert

Gang installed key-logging software at Sumitomo Corporation

International hackers attempt massive heist

High Tech Crime Unit smashes £220m hacking ring

ID theft cons UK public out of £1.3bn

Quarter of UK adults hit by online scammers, finds Which? poll

Government IT regulation sparks fierce debate

Tempers fray at RSA Conference as experts discuss government role in security

Related whitepapers

Related jobs

Most watched

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Google Chrome

Microsoft has no need to worry about Chrome OS

Redmond may actually welcome the new arrival

Dr Aladdin Ayesh

Is it time for the Turing Test to retire?

It is nearly 60 years since Alan Turing devised a...

Security double standards

Broadband provider Tiscali has launched new figures showing an alarming...

Beach

Top 10 holiday gadgets

A wry look at the must-have beach items for any...

Primary Navigation